Skip to content
Help Center

Okta integration overview

View MarkdownContact support4 min read
On this page

Overview

Okta is an Identity and access management (IAM) platform that centralizes and secures user access to applications and services. It acts as a central, secure hub that allows users to log in to multiple apps with a single set of credentials (SSO) while giving IT teams centralized control over access and security.

With Persona’s Okta integration, you can seamlessly embed identity verification throughout the employee lifecycle — from onboarding to account recovery — to protect against phishing, social engineering, and deepfake attacks.

Organizations can:

  • Trigger identity verification during critical moments (e.g., onboarding, password resets, authenticator enrollments)
  • Pull user profile data from Okta to enrich verification workflows
  • Automate account actions like resetting MFA factors or suspending users— without leaving Okta

This integration helps IT and InfoSec teams reduce account takeover risk, streamline account recovery, and deliver faster, more secure access for employees — while maintaining data compliance and supporting distributed teams.

Integration Options

Persona offers three ways to integrate with Okta:

  1. Persona for Identity Verification (IDV) in Okta
  2. Persona’s Okta API marketplace integration
  3. Persona as an Identity Provider (IdP) authenticator

Only options 1 and 3 trigger identity verification. The Okta API marketplace integration is a Workflows integration for reading Okta profile data and taking account actions, and it layers on top of either identity verification method above; see “Choosing your integration method” below to decide between options 1 and 3.

Note: For Okta SCIM and SSO provisioning, please refer to the following articles:

  1. Setting up Okta SCIM
  2. Enabling SAML-based single sign-on (SSO) with Okta for Persona Dashboard

Choosing your integration method

Before you set up either integration, decide which Okta policies you need Persona to protect.

Okta policy types

Okta has two kinds of authentication policies where Persona can be used:

  • Account Management Policies (OAMP): authentication requirements for enrolling or unenrolling authenticators, resetting a password, or unlocking an account. Example triggers: clicking “Forgot password,” activating a new account, or enrolling a new authenticator.
  • App sign-in policies: how a user must authenticate to access an app. Example trigger: signing in to Jira via SSO.

Identity Verification vs. IdP authenticator

Persona for Identity Verification (IDV) in Okta triggers identity proofing just-in-time, only when an employee takes an action a policy protects. An employee who never takes a protected action never sees Persona, and there’s no enrollment step. This method only works with OAMP.

Persona as an Identity Provider (IdP) authenticator requires an employee to enroll in Persona (complete an inquiry) before an authentication policy can use it as a factor. Okta admins can require enrollment, in which case an employee enrolls the next time they sign in. This method works with both OAMP and app sign-in policies.

The tradeoff: an employee who hasn’t enrolled in the IdP authenticator can’t use it as a factor. If password reset is gated behind the IdP authenticator and an employee never enrolled, they can’t self-serve a reset from the “Forgot password” link.

Don’t gate authenticator enrollment behind an Account Management Policy that requires Persona as the IdP authenticator. An employee who hasn’t enrolled yet would have no way to complete the enrollment that policy is protecting.

Feature comparison

FeaturePersona IDVPersona as an IdP authenticator
Supported policiesAccount Management Policies (OAMP) onlyAccount Management Policies and app sign-in policies
Enrollment requiredNoYes

Which method should I use?

If you want to protectUse
Only Account Management Policies (password reset, authenticator enrollment, account unlock)Persona for Identity Verification (IDV). No authenticator enrollment needed.
App sign-in policies (for example, requiring verification to sign in to an app)Persona as an IdP authenticator. Only authenticators are eligible for app sign-in policies.
BothEither. Many customers start with Persona IDV for Account Management Policies and add the IdP authenticator later, since the two are compatible. A customer who wants both from the start can use the IdP authenticator alone, but must require enrollment for every employee up front.

If you plan to use both integration methods, talk to your Persona account team before turning on the second one, so your Persona accounts stay linked to the right employee instead of creating duplicates.

Plans Explained

Okta Integration by plan

Startup ProgramEssential PlanGrowth PlanEnterprise Plan
Okta IntegrationNot AvailableNot AvailableLimitedAvailable

Learn more about pricing and plans.

Last updated on .

Was this page helpful?If something is missing, let us know and we will take a look.
Thanks for the feedback. It helps us improve these docs.